Skip to content

Known CVE

MLflow Webhook SSRF - Unauthenticated Full-Read via Redirect Bypass

MLflow > 3.15.0 contains an information disclosure vulnerability caused by improper validation of webhook URLs allowing attackers to reach internal or cloud metadata services and obtain response details, exploit requires unauthenticated access to the webhook test endpoint.

CVE-2026-64849

Critical2026CVSS 9.3CWE-918

cve2026 · mlflow · ssrf · oast · webhook · oss · vkev · kev

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website